300-740 · Question #49
Refer to the exhibit. An engineer must analyze a segmentation policy in Cisco Secure Workload. What is the result of applying the policy?
The correct answer is B. HR cannot use Telnet to connect to IT by using Rule #2. Option B is correct because Cisco Secure Workload evaluates segmentation rules top-down in order, and Rule #2 explicitly denies Telnet (port 23) traffic from the HR scope to the IT scope - so that rule matches and is applied before any subsequent rules are considered. Why the…
Question
Refer to the exhibit. An engineer must analyze a segmentation policy in Cisco Secure Workload. What is the result of applying the policy?
Exhibit
Options
- AThe default catch-all rule is applied by using Rule #3.
- BHR cannot use Telnet to connect to IT by using Rule #2.
- CHR can use Telnet to connect to IT by using Rule #1.
- DThe explicit deny all rule is applied.
How the community answered
(28 responses)- A7% (2)
- B75% (21)
- C4% (1)
- D14% (4)
Explanation
Option B is correct because Cisco Secure Workload evaluates segmentation rules top-down in order, and Rule #2 explicitly denies Telnet (port 23) traffic from the HR scope to the IT scope - so that rule matches and is applied before any subsequent rules are considered.
Why the distractors are wrong:
- A is incorrect because the catch-all Rule #3 is never reached for this traffic - Rule #2 already matches and terminates evaluation for Telnet from HR to IT.
- C is incorrect because even if Rule #1 permits general connectivity between HR and IT, Rule #2 introduces a more specific deny for Telnet that is encountered in the rule order and overrides any broader permit - Telnet is blocked, not allowed.
- D is incorrect because an explicit deny-all would require a rule that denies all traffic from any source to any destination; what applies here is a specific deny rule (#2), not a blanket deny-all policy.
Memory tip: Think of Secure Workload policies like a bouncer checklist - the first rule that matches the traffic wins, and the line stops there. When a specific "deny Telnet" rule sits above a general "allow" or catch-all, Telnet never makes it past the door.
Topics
Community Discussion
No community discussion yet for this question.
